Last seven days
- First activity
- Sep 20, 2026
- Last activity
- Sep 21, 2026
- Feed role
- C2
- Host form
- 0 IP / 7 hostnames
Blackshades is a Windows-focused remote access trojan that emerged around 2010 and was widely sold on underground forums at low cost, contributing to large-scale global abuse.
Profile source: Mallory opens in a new tabBlackshades
Blackshades is a Windows-focused remote access trojan that emerged around 2010 and was widely sold on underground forums at low cost, contributing to large-scale global abuse. It enabled remote control of infected systems and was used to compromise and spy on hundreds of thousands of computers worldwide. Public reporting and law-enforcement actions have linked its development and sale to Alex Yรผcel and Michael Hogue.
Blackshades provides attackers with broad remote-administration and surveillance capabilities, including unauthorized access to victim machines, file access and modification, keystroke logging, webcam access, payload download and execution, and use of infected hosts as proxies. It has also been used to direct infected systems into distributed denial-of-service activity and has been described as capable of lock-screen style ransom behavior. Operators commonly paired it with obfuscation tools to reduce antivirus detection.
Distribution has been associated with malicious webpages, including drive-by download activity, as well as removable media such as USB devices. The malware was used both by opportunistic cybercriminals and in politically motivated surveillance. It was documented in campaigns targeting Syrian opposition figures, and it also figured in criminal sextortion cases involving covert webcam surveillance and theft of intimate material.
Blackshades became the subject of major international law-enforcement action, culminating in a 2014 coordinated crackdown spanning numerous countries and resulting in arrests, searches, and device seizures. Its history is frequently cited as a prominent example of a commodity RAT marketed as a purported administration tool but broadly used for unauthorized access, surveillance, and other criminal activity.
C2 tracking
Derp observations, rolling seven-day window
Samples
16378f4a25698c0e85335acf2960edd9a1fc523bf4f74b2c70b5da2fe2237f36 8bbc2f805f11819c8a4a494808a976cf5ca6945383a44f47a9fb3dfd93f67e1a bc532403d66eb31f7dc6e42b6bb40a429b4a4ff7d9ab96871a7717c308465dc9 60e2abb186b419412aa38a24ba6478bb0b9b79db064b6e81902f5dcc95913fce a40b4e889df6905891aee3212319d58dec8d208430f411cfd8d082522b0020dc 063eb6987bd6ae30e4f51bf8db5ce215b9d12daa5a79b84e38eaa7177549da77 120a12459f373e67d4d8c1c992da8ef91d8ff23d04a04cfd9f0c065cacd7c798 Reported operators
ALUMINUM SARATOGA ... Tools ... BlackShades, BrittleBush, DarkComet, LastConn, Micropsia, NimbleMamba, PoisonIvy, QuasarRAT, XtremeRat
MITRE ATT&CK
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.